The Federal Information Security Management Act (FISMA) was originally passed in 2002 as part of the Electronic Government Act. FISMA defines a framework of guidelines and security standards to protect government information and operations. FISMA requires all federal agencies to develop, document and implement agency-wide information security programs. NIST SP 800-53 serves as the primary resource that federal agencies use to implement the security controls required by FISMA. The IDs for these controls correspond to those of the NIST 800-53 standard. The version used for this section is NIST 800-53, Rev. 5, September 2020.